Oddbean new post about | logout
 That feeling when you get a vulnerability report for a software library used in your project and the suggested remediation is "none" because no one has patched the vulnerability.

Second place is when the suggested remediation is "none" because other software dependencies have conflicts that prevent you from updating to a patched version. 
 I always read "none" as "hope". 🤣 
 Might as well say "Remediation: Please contribute" or "Patch it yourself" 
 ... double damn! 
 This is a pretty brave post lol 
 House of cards? 
 Casa Etherium related? 
 At least you can patch it yourself. If it was closed source you wouldn't be able to. 
 Everything is broken, nothing is secure.